CVE-2019-13098: Medium severity tronlink wallet vulnerability
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13098?
CVE-2019-13098 has a severity rating of Medium due to the exposure of sensitive information.
How do I fix CVE-2019-13098?
To fix CVE-2019-13098, users should update their TronLink Wallet to a version later than 2.2.0, ensuring proper password storage.
Who is affected by CVE-2019-13098?
CVE-2019-13098 affects users of TronLink Wallet version 2.2.0 on Android devices prior to version 4.1.
What data is exposed in CVE-2019-13098?
CVE-2019-13098 exposes user passwords entered via the registration form, which are logged and accessible by other authenticated users.
Is there a risk of exploitation with CVE-2019-13098?
Yes, CVE-2019-13098 presents a risk as unauthorized users can obtain stored passwords through the logging mechanism.